What the vulnerability does
01Description
A vulnerability was found in Mangboard(WordPress plugin). A SQL-Injection vulnerability was found in order_type parameter. The order_type parameter makes a SQL query using unfiltered data. This vulnerability allows a remote attacker to steal user information.
Explanation of Vulnerability in Simple Terms
02Summary
The Mangboard WordPress plugin version 1.9.9 contains a SQL injection vulnerability in an unauthenticated endpoint. An attacker can craft a malicious request to extract sensitive data from the site's database, including user credentials and private content. No user interaction is required. Update the plugin immediately.
What an attacker can do
03Attacker Capabilities
Read sensitive data from the site database, including user credentials and private posts.
Potential impact on your site
04Site Impact
Attackers can steal user passwords, email addresses, and access private or draft content without logging in.
Conditions required to exploit
05Prerequisites
Network access to the WordPress site; no authentication or user interaction required.
Key dates
06Disclosure timeline
October 26, 2021
CVE published
August 3, 2024
Record updated